SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
- ID
- 27172
- Status
- summarized
- Published
- 22 Sep 2026, 3:52 PM
- Fetched
- 22 Sep 2026, 6:12 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 22 Sep 2026, 6:13 PM
- Tags
- Audience
- developers
What happened
Trellix researchers report that the SideCopy APT group (active since 2019, linked to Pakistan) has expanded spear-phishing targeting from Indian government/defense to academic institutions, using weaponized ZIP archives containing LNK files disguised as PDFs to deliver a multi-stage payload via mshta.exe and reflective DLL loading. The attack chain includes anti-forensic self-deletion and persistence via Windows Registry Run Keys.
Why it matters
This is a geopolitically targeted espionage campaign with no direct impact on Malaysian builders or their tooling. The technical details (LNK spoofing, HTA abuse, reflective DLL loading) are standard APT tradecraft worth noting only if you work in threat intelligence or secure academic/government networks in the region.
Discussion angle
Brief mention only: how LNK-file spoofing and mshta.exe abuse remain reliable initial-access techniques, and whether any audience members supporting academic or government clients in SEA should be flagging similar lures.